v2.3.0-beta.12: quiet status with opt-in detail and ring, push delive… #910
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Continuous integration: typecheck + the full test suite on every push and PR to master. | |
| # Gives PRs (e.g. from collaborators) a green/red signal before merge, and keeps the | |
| # README test badge honest. | |
| name: CI | |
| on: | |
| push: | |
| branches: [master] | |
| pull_request: | |
| branches: [master] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| harness: | |
| name: Harness tests + typecheck (Bun) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| # The load-bearing invariants live in BOTH CLAUDE.md (Claude Code) and AGENTS.md (the | |
| # cross-tool standard). They must stay byte-identical below the title line, or one tool's | |
| # agents follow stale rules. This fails the build the moment they diverge. | |
| - name: CLAUDE.md / AGENTS.md must stay in sync | |
| run: | | |
| if ! diff <(tail -n +2 CLAUDE.md) <(tail -n +2 AGENTS.md) >/dev/null; then | |
| echo "::error::AGENTS.md and CLAUDE.md have diverged below the title line. Keep the invariants identical (only line 1, the '# X — Invariants' title, may differ)." | |
| diff <(tail -n +2 CLAUDE.md) <(tail -n +2 AGENTS.md) || true | |
| exit 1 | |
| fi | |
| echo "✓ CLAUDE.md and AGENTS.md are in sync." | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: latest | |
| # NOT --frozen-lockfile: Dependabot's npm updater bumps package.json but can't update | |
| # bun.lock, so a frozen install would reject every Dependabot PR. Plain install resolves | |
| # the bump and still runs the full suite against it. | |
| - name: Install (root) | |
| run: bun install | |
| - name: Typecheck (root) | |
| run: bun x tsc --noEmit | |
| # Every first-party source file must carry the BUSL-1.1 SPDX header. The pre-commit hook | |
| # (make install-hooks) applies these automatically; this is the backstop for anything that | |
| # slipped through (e.g. a commit made without the hook installed). | |
| - name: License headers (BUSL-1.1) | |
| run: bun run tools/license_headers.ts --check | |
| - name: Harness test suite | |
| run: bun test harness | |
| - name: Install + typecheck (desktop) | |
| working-directory: desktop | |
| run: | | |
| bun install | |
| bun x tsc --noEmit | |
| # ADR-0359 (P-BUILD-GATE.1): COMPILE the two shipped binaries. This step exists because v2.2.1 | |
| # went out with 5249 green tests, two clean typechecks and a green prompt-prefix keystone, and all | |
| # three release legs still died in seconds: omp 16.5.2 added a `legacy-pi-compat` plugin whose | |
| # dynamic `import("omp-legacy-pi-modules")` is meant to be resolved by omp's OWN Bun build plugin, | |
| # and `bun build --compile` chases the literal. Nothing in the suite or either typecheck runs a | |
| # compile, so a dependency bump could break the release and every PR check would still pass. These | |
| # take about 10 seconds combined and they are the only thing here that validates the ARTIFACT | |
| # rather than the source. Renderer bundle included: dev.ts serves the prebuilt artifact. | |
| - name: Compile the shipped binaries (engine + launcher + renderer bundle) | |
| working-directory: desktop | |
| run: | | |
| bun run build-renderer | |
| bun run compile-lucid | |
| bun run compile-engine | |
| # ADR-0177/0178: the RELEASE must BOOT under the packaging filter. This guard materializes a filtered | |
| # install (the extraResources exclusions applied for real) and boots the real dev.ts, then requires | |
| # lazily-imported feature deps to load. A filter/import mismatch - e.g. v1.11.0's `desktop/collab` | |
| # excluded because the filter's `desktop/*.ts` glob was depth-1 only - now FAILS CI, not users. | |
| # (Runs at repo root; needs the root install above so it can link node_modules into the sim.) | |
| - name: Packaged-boot guard (release boots under the packaging filter) | |
| run: bun test desktop/packaged_boot.test.ts | |
| # ADR-0352 (P-TEST.W2): the developer machine is Windows, CI was Linux-only, and the gap grew | |
| # 8 standing environmental test failures that no PR ever saw (ADR-0351 fixed them). This leg | |
| # replicates the LOCAL gate (`make test`'s bun half: the full suite under TEST_IGNORES) on | |
| # windows-latest, so path-separator / path-module / machine-state rot fails the PR that | |
| # introduces it instead of a developer's baseline ritual days later. | |
| gate-windows: | |
| name: Full test gate (Windows) | |
| runs-on: windows-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: latest | |
| - name: Install (root) | |
| run: bun install | |
| - name: Install (desktop) | |
| working-directory: desktop | |
| run: bun install | |
| # The same exclusion-only scope as the local gate (ADR-0303: scope by exclusion, never by | |
| # positional pattern) - vendored trees and the packaged release copy stay out. | |
| - name: Full test suite (Windows) | |
| run: bun test --path-ignore-patterns="desktop/release/**" --path-ignore-patterns="vendor/**" --path-ignore-patterns="lucidaddon_audit/**" | |
| scanner: | |
| name: Unicode scanner tests (Python, ${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-python@v7 | |
| with: | |
| python-version: "3.12" | |
| - name: Pytest (scanner-sidecar) | |
| working-directory: scanner-sidecar | |
| run: | | |
| python -m pip install --upgrade pip pytest | |
| python -m pytest |